Siem Platform Admin
1 day ago
Full time - | - Work From Office - This Posotion is Currently Open **Department / Category**: **ADMIN** - Listed on **Work Location**: **BANGALORE** **Job Descritpion of SIEM Platform Admin**: 7+ Years Relevant Experience - Create innovative solutions to automate and reduce timeframes for operational changes and initial installation of the platform. - Responsible for major SIEM client environmental changes, including upgrades. - Custom parser development. Should have good Regex skills. - Threat detection use-case designing, implementation and fine-tuning. - Create rules/dashboards for compliance and audit requirements. - Security monitoring experience with one or more SIEM technologies (Like QRadar, Splunk, Sentinel, Securonix ArcSight, Sumologic, FortiSIEM, Alien Vault,etc). - Strong understanding of security incident management, malware management and vulnerability management processes. - Strong understanding of networking principles including TCP/IP, WANs, LANs, and commonly used Internet protocols such as SMTP, HTTP, FTP, POP, LDAP. - Strong technical knowledge of Internet security, networking protocols, and related technologies including IDS/IPS, firewalls, content filtering, and packet inspection. - Working knowledge of PowerShell or Python. - Experience with Linux and Unix operating systems. - Working knowledge of the industry models such as the Cyber Kill Chains, Diamond Model and MITRE ATT&CK framework. **Primary Skill**: - Enterprise SIEM Architect exposure. Multiple SIEM deployment experience. SOC Domain Specialized. - Excellent knowledge of one of the SIEM products Qradar Sentinel, Splunk, ArcSight, etc. - Excellent understanding and proven hands-on experience in SIEM concepts such as correlation, aggregation, normalization, and parsing. - Experience with Incident response and Security Operations Center operations. - Experience with deploying and managing a large SIEM deployment. - XXX years of experience with Securonix, Splunk, ArcSight, QRadar, Sentinel SIEM systems. - Excellent knowledge of adversary tactics, techniques and procedures (TTPs) and MITRE ATT & ACK Framework. - Excellent understanding of regular expressions, development of custoM/Flex Parsers. - Excellent Python and Unix Shell scripting skills. - Knowledge on overall GCP, AWS, Azure Cloud infrastructure. - Solid understanding of events, related fields in log records and alerts reported by various data sources such as Windows/Unix systems, IDS/IPS, AV, HIDS/HIPS, WAFs, firewalls, and web proxies. - Excellent understanding of log flow from numerous services within GCP, AWS, Azure cloud and experience with integrating them with 3rd party logging tools including but not limited to Splunk, Qradar, ArcSight, Sentinel, Sumologic and Elastic Cloud. - Good Experience with syslog-ng i.e., configuring complex multi client-server infrastructures. - 5+ years of network security and system security experience, supporting security event management tools (SIEMs). - Excellent understanding of cybersecurity operations, Incident Response processes. - Excellent communication skills. - Good understanding of networking concepts. - Experience interpreting, searching and manipulating data within enterprise logging solutions (e.g. SIEM, IT Service Management (ITSM) tools, workflow, and automation). - In-depth knowledge of security data logs and an ability to create new content on advanced security threats on a need basis as per Threat Intelligence. - Ability to identify gaps in the existing security controls. - Good experience in writing queries/rules/use cases for security analytics (ELK, Splunk or any other SIEM platform) and deployment of content. **Secondary Skills**: - Domain experience of Network Security and Cloud Security. - Security certifications such as CISSP, CEH, Security+. - Preferred experience developing SIEM strategies and implementing these strategies in a global organization. - 3-4 years previous SIEM engineering experience. - Detail-oriented with strong organizational and analytical skills. - Good knowledge of IT, including multiple operating systems and system administration skills. - Good to have certifications: Network Security certification, security plus, CISA, CISSP. **Required Skills for SIEM Platform Admin Job**: **SIEM Architect** **SIEM products Qradar Sentinel** **Splunk** **ArcSight** **SOC** **Azurem GCP** **AWS** **Python and Unix Shell scripting** **Network Security and Cloud Security** **Our Hiring Process**: - ** Screening (HR Round)** - ** Technical Round 1** - ** Technical Round 2** - ** Final HR Round
-
SIEM Admin
4 weeks ago
Bengaluru, India Tata Consultancy Services Full timeDear Candidate Tata Consultancy Services is hiring for Sr SIEM Admin Experience: 8-10 Years Location: Bangalore Role and Responsibility Sr. SIEM admin with minimum 5+ yrs of exp,strong knowledge in Custom parser development, Threat detection use-case designing, implementation and fine-tuning,create rules/dashboards for compliance and audit requirements....
-
Platform Administrator
2 weeks ago
Bengaluru, Karnataka, India ColorTokens Full time**Job Title**:Platform Administrator - NextGen SIEM **About ColorTokens** At **ColorTokens**, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge **ColorTokens Xshield platform**, companies can minimize the impact of breaches by preventing the lateral spread...
-
Platform Administrator
2 weeks ago
Bengaluru, Karnataka, India Colortokens Full time**Job Title**:Platform Administrator - NextGen SIEM **About ColorTokens** At **ColorTokens**, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge **ColorTokens Xshield platform**, companies can minimize the impact of breaches by preventing the lateral spread...
-
SIEM Admin
1 week ago
Bengaluru, Karnataka, India Tata Consultancy Services (TCS) Full time ₹ 12,00,000 - ₹ 36,00,000 per yearSr. SIEM admin with minimum 5+ yrs of exp,strong knowledge in Custom parser developmentThreat detection use-case designing, implementation and fine-tuning,create rules/dashboards for compliance and audit requirements.Strong understanding of security incident management, malware management and vulnerability management processesWorking knowledge of the...
-
SIEM Admin
2 weeks ago
Bengaluru, India Tata Consultancy Services Full timeDear CandidateTata Consultancy Services is hiring for Sr SIEM AdminExperience: 8-10 YearsLocation: BangaloreRole and ResponsibilitySr. SIEM admin with minimum 5+ yrs of exp,strong knowledge in Custom parser development,Threat detection use-case designing, implementation and fine-tuning,create rules/dashboards for compliance and audit requirements.Strong...
-
Bengaluru, Karnataka, India Jinendra infotech pvt ltd. Full timeDear Connections, Microsoft sentinel and ELK in SIEM administration Experience in Enterprise Elastic, kibana and logstash (ELK stack for SIEM) administration. Which includes designing, deploying and managing SOC environments & deploying Microsoft Sentinel Content Hub solution - Configuring analytics, dashboards in ELK & sentinel products. - Relevant...
-
SIEM Integration Architect
4 days ago
Bengaluru, India Unisys Full timeWhat success looks like in this role: Lead the integration of alarm/data feeds from multiple SIEM platforms (e.g., Splunk, LogRhythm, Securonix) into Microsoft Sentinel. Configure and manage Cribl pipelines to collect, filter, transform, and enrich raw data before forwarding to Sentinel. Design and implement data normalization strategies to ensure consistent...
-
SIEM Engineeer
4 days ago
Bengaluru, India ScaleneWorks Full time"Essential Job Functions:- Individuals at this job are responsible for managing SIEM infrastructure like Microsoft Azure Sentinel and / or other SIEMs Working knowledge of Microsoft Azure cloud platform, log analytics workspaces. Excellent knowledge of KQL (Kusto Query Language). Writing SIEM rules (Cross device and complex correlation) to implement...
-
SIEM Integration Architect
2 days ago
Bengaluru, India Unisys Full timeJob Description What Success Looks Like In This Role - Lead the integration of alarm/data feeds from multiple SIEM platforms (e.g., Splunk, LogRhythm, Securonix) into Microsoft Sentinel. - Configure and manage Cribl pipelines to collect, filter, transform, and enrich raw data before forwarding to Sentinel. - Design and implement data normalization strategies...
-
SIEM Engineer
2 weeks ago
APAC - India - Bengaluru - Sunriver Autodesk Full time ₹ 12,00,000 - ₹ 24,00,000 per yearJob Requisition ID # 25WD92686Position OverviewAutodesk is seeking a highly skilled SIEM Engineer to manage and enhance our SIEM platform. This role involves working closely with the SOC, Detection Engineers, Threat Hunters, Security Logging, and SOAR teams to develop, evolve, and fine-tune detections, alerts, and other SIEM configurations to protect...